DOM-Based XSS Vulnerability in Dobase Shared Folder Image Gallery
CVE-2026-54165

6.4MEDIUM

Key Information:

Vendor

Smgdkngt

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-54165?

Dobase, a self-hosted workspace with available tools, is impacted by a stored DOM-based XSS vulnerability in the public shared-folder image gallery. In the affected versions, an attacker can manipulate a file's name due to lack of sanitation, allowing the payload to be injected into the page via the ERB-escaped data-name attribute. This poses a significant risk as any authenticated user sharing a folder can unknowingly spread the malicious code to anyone accessing the public share link. Notably, the global Content-Security-Policy is only report-only, which fails to mitigate the XSS, enabling execution of injected scripts.

Affected Version(s)

dobase < 2026.06.03

References

CVSS V4

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.